Review Kubernetes TLS cipher suites

Use secure TLS cipher suites supported by your Kubernetes version and clients.

Description

Allowing insecure cipher suites can weaken protection even when TLS is enabled. Remove suites classified as insecure by the supported version from API server and kubelet configurations.

Omitting a cipher list uses implementation defaults and does not itself mean weak encryption. This setting does not control TLS 1.3 cipher suites.

Potential impact

  • Negotiating an insecure suite can weaken protection of encrypted traffic.
  • Retaining only unsupported suites can prevent legitimate clients from connecting.

Remediation

  • Select suitable suites such as AES-GCM or ChaCha20-Poly1305 from your version’s recommended list.
  • Review the minimum TLS version, certificate type and client compatibility together.
  • Test actual TLS negotiation and normal connectivity, and verify that insecure suites are not accepted.

Examples

These excerpts separately show kubelet and historical API server cipher arguments. They are not a complete replacement for the same process; use your actual version, certificates and execution image.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: foo/bar
      command: ["kubelet"]
      args:
        [
          "--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256"
        ]

TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 is allowed. The current Kubernetes reference classifies this suite as insecure.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver"]
      args:
        [
          "--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
        ]

AES-GCM suites are specified. Verify support in your version, serving certificate and clients.

References